Advanced Persistent Threats (APTs) are  a growing concern in the security industry and are aggressive in  nature. It uses multiple phases and advanced techniques to break into a  network, avoid detection, and harvest valuable information over the long  term. APTs targets specific target for extremely high value data in  specific organization and are different from other types of hacking  activities. These threats can steal organization's assets for monetary  gain or for political cause. It can also disrupt core infrastructure in  an organization.
A  custom designed APT malware can exploit zero-day vulnerabilities and  can evade traditional defenses. This can then be combined with physical  theft and clever social engineering in targeted “phishing” attacks. In  the end, APTs harness the full spectrum of logical, physical, and social  attack vectors. They exhibit no single activity pattern, making them  difficult to detect.
Phases of APT
Different phases of APT can be summarized as below
- Reconnaissance: Attacker leverages information from a variety of factors to understand their target
- Incursion: Attackers break into network by using social engineering to deliver targeted malware to vulnerable systems and people
- Discovery: Once in, the attackers stay "low and slow" to avoid detection. They then map the organization's defenses from the inside and create a battle plan and deploy multiple parallel kill chains to ensure success
- Capture: Attackers access unprotected systems and capture information over an extended period. They may also install malware to secretly acquire data or disrupt operations
- Exfiltration: Captured information is sent back to attack team's home base for analysis and further exploitation fraud- or worse.
How to get protected?
To  guard against APT attacks, organizations must develop an in-depth  strategy across logical, physical, and social boundaries. SIEM tool can  be used to analyze events and create alert/correlation rules for APT  Detection and then design strategy to combat such attack. Some of the  rules that can be built to detect APTs are as follows
- Abnormal Internal Connections
- Abnormal Outbound Connections
- Blacklist Location Authentication
- Concurrent VPN from Multiple Countries
- Concurrent VPN from Multiple Regions
- Critical Event After Attack
- Failed Account Probe
- Failed Account Probe on Multiple Hosts
- Port Scan then Attack
- Account Creation
- Attack then External Connection
- Brute Force Auth
- Log Cleared
- Data Exfiltration
- DDoS Attack
- Identifying Cross-Site Scripting (XSS) Attacks
- Identifying Excessive HTTP Errors
- Identifying SQL Injection Attacks
- Identifying Traffic from Low Reputation Hosts
- Lateral Movement then Account Creation
- Lateral Movement with Account Sweep
- Numerous Internal Failed Auths
- Outbound Traffic Rate Increase
- System Time Change
- Threat Intelligence Connection
- High Risk Vulnerable Sources (Correlate the data from vulnerability management)
 
 
No comments:
Post a Comment